|
 |
Tuesday, September 10, 2002 |
New NIST Security Documents
NIST has just released several new security documents with standards for federal agencies. I would suggest that state agencies pay attention to some of the NIST recommendations as well.
NIST also maintains the ICAT database, which is a searchable index of computer vulnerabilities. The document on handling security patches suggests the creation of a patch and vulnerability group (PVG). Looks like a good idea. This group would be responsible for (among other things):
- Creating an organizational hardware and software inventory
- Identifying newly discovered vulnerabilities and security patches
- Prioritizing patch application
- Creating an organization-specific patch database
- Testing patches for functionality and security (to the degree that resources allow)
- Distributing patch and vulnerability information to local administrators
- Verifying patch installation through network and host vulnerability scanning
- Training system administrators in the use of vulnerability databases
- Deploying patches automatically (when applicable)
- Configure Automatic Update of Applications (when applicable).
9:29:43 AM
|
|
© Copyright 2002 David Fletcher.
|
|
|
|
September 2002 |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
28 |
29 |
30 |
|
|
|
|
|
Aug Oct |
|
Blogs in the Utah Blog Cluster
|